Privacy notice

Last updated: 9 September 2026 · Version 1.0

Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Applies to the CBAM Calculator application and to the service's informational website.

The Carbonvia service (provisional name) is provided by Pipex Energy S.r.l.; inside the application the service is called CBAM Calculator. The texts below are the same as those published in the application.

This is a courtesy translation. The Italian version prevails for legal purposes.

1. Data controller

Pipex Energy S.r.l., registered office Viale Gian Galeazzo 15, 20136 Milan (MI), Italy, VAT and tax code 11674300964, Milan Monza Brianza Lodi Companies Register REA MI-2618541, share capital EUR 100,000.00 fully paid, certified email pipexenergy@pec.it.

Privacy contact and exercise of rights: privacy@pipexenergy.it.

No Data Protection Officer has been appointed, as the conditions of Article 37 GDPR do not apply.

2. Who this notice is for and in which role we process data

CBAM Calculator is a service for businesses and professionals (importers, customs brokers, consultants) to calculate and manage obligations under the CBAM mechanism (Regulation (EU) 2023/956). We process personal data in two distinct roles.

a) As an independent controller, for the data needed to provide and protect the service: application users (employees or collaborators of the Customer who sign in with an account), the Customer's administrative and billing contacts, website visitors and people who contact us.

b) As a processor on behalf of the Customer (Article 28 GDPR), for the data the Customer uploads into the application in the course of its business: records of foreign suppliers, producers and installations (including name, email and phone of their contact persons), customs declarations and uploaded documents, emissions data, simulations and declarations. For this data the controller is the Customer; data subjects should contact the Customer, and we assist it under the Data Processing Agreement (page dpa.html). If you see your data in CBAM Calculator as a supplier of one of our Customers, the controller is that Customer.

3. What data we process, why and on which legal basis

PurposeDataLegal basisRetention
Account creation and management, authentication, invitations, password reset, two-factor authenticationFirst name, last name, email, password (hash only), language, email verification status, last sign-in, two-factor secret (encrypted), role in the company, accepted Terms version with date and IP addressPerformance of the contract (Art. 6.1.b)Duration of the contract; deletion within 60 days after the company is deleted. Accounts removed from every company are anonymised after 30 days. Unaccepted invitations expire after 7 days
Service security: abuse prevention, sign-in lockout, rate limiting, incident investigationIP address, date and time, authentication outcome, failed attempt counter, technical logs with pseudonymised emailLegitimate interest (Art. 6.1.f) in the security of the service and of Customers' dataTechnical and monitoring logs: 90 days. API usage logs: 90 days
Audit trail: who created, changed, deleted or exported what, required by Customers for their CBAM declaration responsibilityUser email, action, resource, before/after difference, IP address, date and timePerformance of the contract and legitimate interest of the Customer and ours in traceability24 months, then automatic deletion
Billing and subscriptionsCompany name, VAT/tax code, address, SDI recipient code, certified email, billing email and phone, VIES check result, plan, subscription status, Stripe identifiers. We do not process payment card data, which is handled exclusively by StripePerformance of the contract (Art. 6.1.b) and legal tax and accounting obligations (Art. 6.1.c)10 years from the end of the financial year (Art. 2220 Italian Civil Code)
Service communications: email verification, sign-in codes, security alerts, trial expiry, invoices, changes to the Terms, company deletionEmail, namePerformance of the contractDuration of the contract
Support and contact requestsData provided in the request (name, email, company, content)Pre-contractual measures or performance of the contract (Art. 6.1.b)24 months after the request is closed
Commercial communications about new features or Pipex servicesEmailConsent (Art. 6.1.a), or legitimate interest for communications to active Customers about similar services (Art. 130(4) Italian Privacy Code), always with the right to objectUntil withdrawal or objection
Defence of rights in disputesThe above data as neededLegitimate interest (Art. 6.1.f)Applicable limitation periods

Providing the data marked as mandatory in the forms is necessary to use the service; without it the account cannot be created or invoices issued.

The service is for businesses and professionals only and is not intended for persons under 18.

4. Artificial intelligence features

The Customer may choose to have uploaded customs declarations read automatically. In that case the document is processed by Microsoft Azure services (Azure AI Document Intelligence and Azure OpenAI, gpt-4o model) hosted in the Sweden Central region, which return a proposal of extracted data. Microsoft does not use this data to train models.

No data extracted by artificial intelligence enters a calculation, an export or a declaration without the explicit confirmation of a person at the Customer: there are no decisions based solely on automated processing within the meaning of Article 22 GDPR. For each operation we record the user, the number of pages and the estimated cost for billing purposes.

5. Recipients and processors

Data is processed by authorised Pipex Energy staff and by the following suppliers, acting as processors under contracts compliant with Article 28 GDPR:

SupplierServiceLocation and place of processing
Microsoft Ireland Operations LtdHosting (Azure Container Apps, PostgreSQL database, file storage, Key Vault, logs and monitoring), Azure AI Document Intelligence, Azure OpenAIIreland; data centre in the Sweden Central region (Sweden, EU)
Brevo (Sendinblue SAS)Delivery of transactional emailsParis, France (EU)
Stripe Payments Europe LtdPayments and subscription management. Stripe is an independent controller for payment data under its own privacy noticeDublin, Ireland (EU)

We may disclose data to public authorities where required by law, and to advisers (accountant, lawyers) for tax compliance or to defend our rights. We do not sell data and do not share it for third-party marketing.

When the Customer accesses the service through a partner (consulting firm or customs broker acting on its behalf), the partner sees the Customer's company data under the mandate received from the Customer.

6. Transfers outside the European Union

By design, data is stored and processed in the European Union (Sweden, France, Ireland). The suppliers above have parent companies in the United States and may access data in limited cases (technical support, security). Such access is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) and by the suppliers' certification under the EU-US Data Privacy Framework. A copy of the safeguards is available on request at privacy@pipexenergy.it.

The application and the website do not load resources from third-party servers: fonts are hosted on our own systems.

7. Security

Main measures: encryption in transit (TLS) and at rest, database reachable only from a private network, isolation of each Customer's data through database-level Row-Level Security, passwords stored as hashes only, two-factor authentication available, automatic lockout after failed attempts, secrets in Azure Key Vault, audit logs, automatic daily backups kept for 7 days, pseudonymisation of identifiers in technical logs, periodic security review.

In case of a data breach posing a risk to data subjects, we will notify the Italian supervisory authority within 72 hours and the affected Customers without undue delay.

8. Where the infrastructure is located (Article 28 of Regulation (EU) 2023/2854, Data Act)

The ICT infrastructure delivering the service is located in the Microsoft Azure Sweden Central region, under Swedish and European Union jurisdiction. To prevent unauthorised access by third-country authorities: data does not leave the EU by design, encryption at rest is active, administrative access is limited to named identities with two-factor authentication and to authorised IP addresses, and any request for access by an authority would be assessed case by case and communicated to the Customer where permitted by law.

9. Your rights

You may at any time request access to your data, rectification, erasure, restriction of processing, portability (Art. 20) and object to processing based on legitimate interest; you may withdraw consent without affecting processing already carried out. Write to privacy@pipexenergy.it; we reply within one month.

If you are a user of a Customer, many operations (profile changes, two-factor activation, full data export, company deletion) are available directly in the application or through your company's administrator.

You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the authority of the EU country where you reside.

10. Changes

We will update this notice when processing activities or suppliers change. Substantial changes will be communicated by email to Customers' administrators at least 30 days in advance. Previous versions are available on request.